Microsoft Secure Score

Microsoft Secure Score for MSPs: Track It Across Every Customer Tenant

Microsoft Secure Score gives each Microsoft 365 tenant a single security rating and a ranked list of improvement actions. MSPs need it in context — tracked per customer, compared across the portfolio, watched for regressions, and paired with Conditional Access, Defender, identity risk, and external findings. This is how to run Secure Score across a book of business.

What Microsoft Secure Score measures

Secure Score is Microsoft’s built-in security rating for a Microsoft 365 tenant. It is a useful, standardized input for posture reviews — not a complete MSP operations model on its own.

A single 0–100% rating per tenant

Secure Score expresses a tenant’s posture as a percentage of the points available to it. Microsoft assigns points to improvement actions across identity, devices, apps, and — with the right licensing — data, weighted by expected risk reduction. The score updates automatically as configuration changes and as Microsoft adds or retires recommendations.

Because every tenant is scored the same way, Secure Score is a fast common language between an MSP and a customer: one number, a direction of travel, and a ranked list of what to fix next.

Microsoft-maintained improvement actions

Each recommendation carries a point value, an implementation-effort rating, a user-impact note, and a link into the relevant admin center. Actions can be marked as planned, resolved through a third party, or risk-accepted — convenient for tracking, but it also means a score can rise without the underlying control actually being in place.

Where it comes from

Secure Score is surfaced in the Microsoft Defender portal and is available programmatically through the Microsoft Graph security API (secureScores and secureScoreControlProfiles). Both routes are per tenant.

What a typical score looks like

There is no universal “good” number — it depends on licensing, industry, and risk tolerance — but independent assessments consistently put unremediated tenants low. GCS Technologies reports that organizations new to the platform or with limited licensing land around 30–50%, and mid-market tenants it assesses start between 40% and 60%; Trusted Tech Team puts mid-market organizations in the same 40–60% band. Above roughly 60% is generally considered strong. Most tenants an MSP inherits at onboarding sit well below that.

Where native Secure Score falls short for MSPs

It is single-tenant

Secure Score is displayed one tenant at a time. To see it across a customer base you are either logging into every Defender portal in turn or scripting the Graph API and storing the results yourself. Microsoft 365 Lighthouse aggregates some of this, but it is tied to the CSP/GDAP partner model and still stops short of a full MSP operations view.

No long-run history or regression alerting

The native view shows the current score and a short trend. It does not keep a durable per-customer history, and it does not tell you when a score drops. A disabled Conditional Access policy, a new MFA exclusion, or an admin change can move a tenant backwards between your scheduled reviews without anyone noticing.

Recommendations are not workflow

Improvement actions are a list, not tickets. They are not assigned to a technician, not routed by customer or severity, and not connected to your PSA. Turning “40 open actions across 25 tenants” into prioritized work is left to the MSP.

The number can be inflated

Marking actions as risk-accepted or covered by a third party raises the score without changing the tenant. A high Secure Score is evidence worth reviewing, not proof that a tenant is hardened.

It only covers Microsoft

Domains, DNS and email authentication, public-facing websites, TLS certificates, and non-Microsoft SaaS are outside Secure Score entirely — yet they are part of most customer security reviews. Secure Score is one signal in a broader posture picture that also includes the external attack surface.

How to track Secure Score across customer tenants

Manually, tenant by tenant

Open each customer’s Defender portal, read the score, note the open actions. This is fine for one to three tenants and does not scale past that — no roll-up, no history you control, no alerting.

With the Microsoft Graph API

Register a multi-tenant app with SecurityEvents.Read.All, consent it into each customer tenant through GDAP, and call GET /security/secureScores on a schedule, looping over every tenant. This gives you the raw numbers to build your own dashboard — you still own storage, history, trend detection, alerting, and getting the score into customer reports.

This is the right approach for MSPs with the automation capacity to build and maintain it. For everyone else, a platform that already does the collection, history, and reporting is faster to stand up.

With SecurityScore.me

SecurityScore.me reads Secure Score through Microsoft Graph for every connected customer and keeps it in that customer’s workspace next to Conditional Access, Defender for Endpoint, Entra identity risk, and any external findings. The organization view lists every customer’s current score and last assessment together, 90-day trends flag tenants that are slipping, and the score flows into the customer-ready report with the rest of the posture picture.

Priority customers

Using Secure Score in MSP operations

Customer reviews and QBRs
Put the current score, the 90-day trend, and the top open improvement actions in the client-ready report — with Conditional Access, Defender, and open findings on the same page.
Regression alerting
Get told when a customer’s score drops, so a disabled policy or a new exclusion is caught in days rather than at the next quarterly review.
Prioritized remediation
Work the highest-impact improvement actions across the whole portfolio, ranked alongside severity-scored findings instead of tenant by tenant.
Baselines and drift
Set a target score per customer tier and watch for drift between assessments rather than rediscovering regressions by hand.
Onboarding evidence
Capture a baseline score the day a customer is connected, then show the delta at the 90-day review as proof of the work done.
Needs attention

Related pages

Frequently asked questions

Next steps

See Secure Score across your whole customer portfolio

Connect your customers’ Microsoft 365 tenants and track Secure Score, trends, and improvement actions from one workspace — with Conditional Access, Defender, and external findings alongside.